SonyBMG and First4Internet Release Mysterious Software Update
SonyBMG and First4Internet, the companies caught installing rootkit-like software on the computers of people who bought certain CDs, have taken their first baby steps toward addressing the problem.
Context & Ripple Effects
Days after Mark Russinovich's Sysinternals investigation exposed a rootkit hidden on SonyBMG music CDs and Freedom to Tinker argued that the DRM scheme made customers' computers less secure, SonyBMG and its DRM vendor First4Internet are now shipping their first response. The move follows Sony's earlier pledge to patch the copy-protected CDs, but the update arrives with no documentation of what it changes or removes.
First-order effects
- Customers who played the affected CDs get an undocumented software update whose behavior is not publicly specified — they must either trust it blindly or leave the rootkit-like code in place on their machines.
- Security researchers gain a new artifact to dissect immediately; given how quickly flaws were found in the original scheme, the update itself becomes the next audit target.
Second-order effects
- Attackers are already weaponizing the installed code — [[a:1175817|World of Warcraft cheat hackers have been using the Sony BMG rootkit to hide their own malware]] — which turns every day of an opaque, incomplete fix into direct exposure for affected PCs.
- The episode forces the broader DRM industry to confront that stealth installation is a liability rather than protection, raising legal and PR costs for any vendor considering kernel-level hiding of copy-protection code.
Third-order effects
- If the pattern holds — vendor-installed hidden software justified by IP enforcement — expect regulators, antivirus firms, and class-action litigators to treat undisclosed system modifications as a standing security category, a precedent echoed years later when Lenovo shipped laptops with an anti-theft rootkit that reinstalled unwanted software.
- The structural lesson is that content-industry DRM built on compromising the host OS will keep colliding with the security community, pushing labels toward less invasive schemes or abandoning CD copy-protection altogether.
The trend: This is one data point in the recurring collision between media-industry copy protection and user security, where DRM vendors' hidden system-level software keeps being exposed and punished by researchers, attackers, and eventually regulators.